@phoronix You should probably check the "Again, to be completely clear, this just is affecting AUR packages and the official Arch Linux packages". I assume you meant NOT the official Arch Linux packages.
Airoha Bluetooth RACE vulnerabilities (CVE-2025-20700/20701/20702)
Blog post: https://t.co/ZQ1PSdKoX0
White paper: https://t.co/cPOi3TXYSa
Credits Dennis Heinze, Frieder Steinmetz (@ERNW_ITSec)
#infosec#bluetooth
CVE-2024-1086 (Local Privilege Escalation)
-
While the xz backdoor was all over the place, this incredible exploit seemed to "slip" by!
-
This is working on most Linux kernels from 5.14 to v6.6
-
Repo: https://t.co/C9wmPd7LuS
-
Creator: @notselwyn
List with more than 300 links to blog posts, write-ups and papers related to cybersecurity, reverse engineering and exploitation (continuously updated)
https://t.co/BFgAhy4ruL
#cybersecurity#infosec
@jonathandata1 For anyone curious. This appears to be based on CVE-2016-4030, CVE-2016-4031 and CVE-2016-4032 as described here in 2016: https://t.co/JnfSRJJfFZ
Bypass read-out protection (RDP) of STMicroelectronics STM32F1 series.
(credits Marc Schink and Johannes Obermaier)
https://t.co/2tlg8vHELR
#cybersecurity#iot#embedded
A lot of people said sniffing a TPM requires advanced knowledge and equipment - so let’s change that!
Soon a couple of pogo-pins and a @Raspberry_Pi Pico will be enough 😀
Fun fact:
Let's say you have SSRF and you wanna hit 192.168.1.1 but the IP is blocked. You probably know to try encoding but here's some lesser known bypass techniques:
192.168.257
(3rd octect sorta "overflows" into the 4th)
192。168。1。1
(unicode normalization turns 。 into .)
@MalainineME@amnesty@citizenlab You know him personally that you are 'sure' or where does your confidence come from?
Just because someone is modest and doesn't oversell their expertise in a subject they might not be as confident in as in their main subject doesn't mean they don't have expertise in it.
@jonathandata1@MalainineME@virusbtn@maldr0id@citizenlab@amnesty Yes, I did get the color wrong. You rightfully called me out on that. But I'm glad we can agree that it's an iPhone 11! I still stand with the rest of my statement though. You keep proving it to be correct :)
@MalainineME I don't know what relevance that would have for his "disagreement". Also I never mentioned that I don't like him. I actually often find him very entertaining! I just simply do not agree with a lot of what he publishes.
@jonathandata1 @thisisinfosec @NHSEnglandLDN@Anisha12 Believe it or not, 10 years can make quite a difference in terms of relevance. That you even had to go back so far to dig this out is quite telling. But I guess you desperately needed that achievement.
@jonathandata1 @thisisinfosec @NHSEnglandLDN@Anisha12 You know, usually I'd give people the benefit of the doubt but you have done the exact same in the past, leaving out context, cutting out sections that on its own might give a different impression than what was originally said. At some point it's not a coincidence.
@jonathandata1 @thisisinfosec @NHSEnglandLDN@Anisha12 Sure, so why did you not post the screenshot to the web archive in the first place and instead invested time in editing the photo in, changed the color scheme of the post and cut it off where the date would have been?